Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Orangehrm:
>> Orangehrm
>> 4.10
Security Vulnerabilities
CVE-2022-27107
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter
CVSS Score
5.4
EPSS Score
0.002
Published
2022-04-06
CVE-2022-27108
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
CVSS Score
4.3
EPSS Score
0.001
Published
2022-04-06
CVE-2022-27109
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-04-06
CVE-2022-27110
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-04-06
Page 1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved